Policy pursuant to European Regulation no. 2016/679 (GENERAL DATA PROTECTION REGULATION – GDPR)
DATA CONTROLLER
RIVERCLACK SPA with headquarters in Via Belvedere 78, 37026 Pescantina (VR), Italy, Tax Code and VAT T00251170239 (hereafter: “Owner”).
The processing of personal data is carried out by means of operations listed under Article 4 of this Privacy Policy and Article 4 no. 2) GDP, namely: collection, registration, conservation, consultation, elaboration, modification, selection, extraction, evaluation, use, interconnection, blocking, communication, deleting and destruction of data. Personal data are subjected to both paper, electronic and/or automated processing by authorized parties in compliance with the principles of lawfulness, purpose limitation and data minimization.
Contractual purpose: execution of a contract to which you are a party
Once the retention periods indicated above have expired, your personal data will be destroyed, deleted or made anonymous, compatibly with the technical cancellation and backup procedures.
Personal data provision already mentioned in points 4.1 and 4.2 is mandatory.
The refusal to provide the aforementioned personal data does not allow using the services/contents offered by the site.
Data provision for the purposes referred to in point 4.3 is optional.
Data may be processed by external parties acting as Data Controllers such as, for example, supervisory and control authorities and bodies and in general public or private entities entitled to request the data, as well as persons, companies, associations or professional firms, which provide assistance and consultancy activities. The data may also be processed, on behalf of the Data Controller, by external parties designated as data controllers pursuant to art. 28 of the GDPR, who are given adequate operational instructions. These subjects are essentially included in the following categories:
a. companies that offer website and information system maintenance services;
b. companies that carry out management and maintenance services on the Data Controller's database.
Personal data will not be disclosed, but may possibly be transmitted to Public Authorities who may specifically request them from the Data Controller for administrative or institutional purposes, in accordance with the current national and European legislation provisions.
To achieve the aforementioned purposes, the Data Controller may rely on software solutions providers, web applications and storage services which are also provided via cloud computing systems on servers that may be located in non-EU countries.
In case of any personal data getting transferred to these countries, in the absence of an adequacy decision from the European Commission, personal data transfers will only be possible when proper guarantees of contractual or pactional nature are provided by the Data Controller and the Managers involved, including binding corporate rules and standard contractual data protection clauses. Transfer of your Personal Data to third countries outside the European Union (in the absence of an adequacy decision or other proper measures as described above) will be carried out only according to your explicit approval or in the cases provided for in the GDPR and will be in any case managed in your interest.
Your data may be processed the Data Controller's corporate functions employees who are responsible to pursue the purposes indicated above; accordingly, they have received adequate operating instructions and they have been expressly authorized to process data.
Data collected while browsing the Site (referred to in point 4.2) may be processed by employees, Owner collaborators or external parties, as data processors and managers, who carry out technical and organizational website tasks on behalf of the Owner.
Under certain conditions you have the right to ask the Owner:
If you wish to lodge a complaint pursuant to art. 77 GDPR to the competent supervisory authority based on your habitual residence, place of work or place of violation of your rights; for Italy, the person responsible is the Guarantor for the protection of personal, who can be contacted via the website contact details http://www.garanteprivacy.it.
The exercise of these rights is subject to some exceptions aimed at safeguarding public interest (for example the prevention or identification of crimes) and our interests (for example the maintenance of professional secrecy). If you happen to exercise any of the aforementioned rights, it will be our responsibility to verify that you are entitled to exercise it and we will give you feedback.
Your personal data will be processed with automated tools in the strictly necessary time to achieve the purposes for which they were collected and in compliance with the principle of necessity and proportionality, avoiding processing personal data if the operations can be carried out through the anonymous use of data or through other methods. We have adopted specific security measures to prevent personal data loss, illicit or incorrect use and unauthorized access but please do not forget how essential it is for the security of your data that your device is equipped with tools such as constantly updated antivirus and that the provider providing you with Internet connection guarantees secure transmission of data through firewalls, anti-spamming filters and similar safeguards.
To exercise the rights referred to in point 8, you can contact the owner at the following addresses: RIVERCLACK SPA with registered office in Via Belvedere 78, 37026 Pescantina (VR), Italy, Fiscal Code. and Part. VAT IT00251170239, T +39 045 773 21 77, F +39 045 773 29 70, privacy@iscom.it
Versatile, Easy-to-Install, Long-Lasting, Sustainable